Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2861▲ 226 respecto a la semana anterior
Críticas / altas1331▼ 99 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
3905 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.96% | — | Apache Openoffice | 24/3/2023 | 17/6/2026 | Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice,… | |
| Modificada | Alta (7.8) | 0.87% | — | Apache Openoffice | 24/3/2023 | 17/6/2026 | Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory. | |
| Modificada | Media (4.3) | 1.8% | — | Apache Tomcat | 22/3/2023 | 17/6/2026 | When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could… | |
| Modificada | Alta (7.5) | 1.5% | — | Apache Sling Resource Merger | 20/3/2023 | 17/6/2026 | Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache Sling Resource Merger: from 1.2.0 before 1.4.2. | |
| Modificada | Media (5.3) | 1.4% | — | Apache Airflow | 15/3/2023 | 17/6/2026 | Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. | |
| Modificada | Alta (7.5) | 1.9% | — | Apache Log4j | 10/3/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on which logging component is in use) to be processed could… | |
| Modificada | Crítica (9.8) | 4.8% | 💥 PoC | Apache Dubbo | 8/3/2023 | 17/6/2026 | A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and prior versions. | |
| Analizada | Alta (7.5) | 2.1% | — | Apache Http ServerDebian LinuxUnbit Uwsgi | 7/3/2023 | 17/6/2026 | HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. | |
| Modificada | Crítica (9.8) | 85% | 💥 PoC | Apache Http Server | 7/3/2023 | 17/6/2026 | Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target… | |
| Modificada | Alta (7.5) | 1.5% | — | Apache-airflow-providers-amazon | 24/2/2023 | 17/6/2026 | Generación de vulnerabilidad de mensaje de error que contiene información confidencial en el proveedor AWS Apache Airflow. Este problema afecta a las versiones del proveedor AWS de Apache Airflow anteriores a la 7.2.1. | |
| Modificada | Crítica (9.8) | 2.0% | — | Apache-airflow-providers-apache-hive | 24/2/2023 | 17/6/2026 | Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3. | |
| Modificada | Crítica (9.8) | 1.9% | — | Apache-airflow-providers-apache-sqoop | 24/2/2023 | 17/6/2026 | Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1. | |
| Modificada | Alta (7.5) | 1.8% | — | Apache-airflow-providers-google | 24/2/2023 | 17/6/2026 | Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | |
| Modificada | Crítica (9.8) | 1.6% | — | Apache-airflow-providers-google | 24/2/2023 | 17/6/2026 | Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | |
| Modificada | Media (6.5) | 1.1% | — | Apache Sling I18n | 23/2/2023 | 17/6/2026 | Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the repository in a location the author has write access to. As these translations are used across the whole product, it allows an author to change any text or dialog in the product.… | |
| Analizada | Crítica (9.8) | 1.5% | — | Apache Kerby Ldap Backend | 20/2/2023 | 17/6/2026 | Existe una vulnerabilidad de inyección LDAP en LdapIdentityBackend de Apache Kerby anterior a 2.0.3. | |
| Modificada | Alta (7.5) | 49% | 💥 PoC | Apache Commons FileuploadDebian Linux | 20/2/2023 | 7/10/2026 | Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. | |
| Modificada | Alta (8.8) | 1.2% | — | Apache Shenyu | 15/2/2023 | 17/6/2026 | Vulnerabilidad de gestión de privilegios inadecuada en Apache Software Foundation Apache ShenYu. ShenYu Admin permite a los administradores de bajo nivel con privilegios crear usuarios con privilegios más altos que los suyos. Este problema afecta a Apache ShenYu: 2.5.0. Actualice a Apache ShenYu 2.5.1 o aplique el… | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Sling JCR Base | 14/2/2023 | 17/6/2026 | Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access data stored in a remote location via JDNI and RMI. Users… | |
| Modificada | Alta (7.5) | 1.4% | — | Apache Nifi | 10/2/2023 | 17/6/2026 | El procesador ExtractCCDAAttributes de Apache NiFi 1.2.0 a 1.19.1 no restringe las referencias a entidades externas XML. Las configuraciones de flujo que incluyen el procesador ExtractCCDAAttributes son vulnerables a documentos XML maliciosos que contienen declaraciones de tipo de documento con referencias a entidades… | |
| Modificada | Alta (8.8) | 96% | 💥 Exploit | Apache Kafka Connect | 7/2/2023 | 17/6/2026 | A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on Kafka Connect clusters… | |
| Modificada | Media (6.1) | 1.4% | — | Apache Sling CMS | 4/2/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in multiple features. Upgrade to Apache Sling App CMS >= 1.1.6 | |
| Modificada | Alta (8.1) | 0.96% | — | Apache AGE | 4/2/2023 | 17/6/2026 | There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for PostgreSQL 12, all versions up-to-and-including 1.1.0, when using those drivers. The fix is to update to the latest Golang and Python drivers in addition to the latest version… | |
| Modificada | Crítica (9.8) | 1.3% | — | Apache Inlong | 1/2/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223 https://github.com/apache/inlong/pull/7223 to… | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Inlong | 1/2/2023 | 17/6/2026 | Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214 https://github.com/apache/inlong/pull/7214 to solve it. |